☰ All Resources
🟢 Presentation🟣 Hallucinations🔴 Compliance💜 FAQ
AI Data Protection · What Nobody Tells You
The tools you've trusted for years
just got a lot more complicated.
Word. Excel. QuickBooks. Google Docs. Every major productivity tool now has AI built in — and most people don't realize what that means for their data. Two acronyms, BAA and DPA, are what stand between your organization and a serious compliance violation. Hover the numbered badges to see sources.
First, the vocabulary
BAA
Business Associate Agreement
A legal contract a vendor must sign before they're permitted to access, store, or process protected health information. Without one, your organization is the one in violation — not the software company.
Required under HIPAA
DPA
Data Processing Agreement
A contract specifying exactly what a vendor can do with personal data you give them — including whether they can use it to train AI models. Applies to any client, employee, or patient personally identifiable information.
Required under GDPR / state privacy laws
How it happens — a pattern playing out everywhere
⚠ Real-World Patterns — Happening Across South Dakota Right Now
Real-world AI vulnerabilities have real-world consequences for your customers and clients.
It usually starts with efficiency. Someone in the organization reaches for a familiar tool — Excel, QuickBooks, Google Docs, a free AI assistant — to solve a problem faster. It works. The software they've trusted for years now has an AI button built right in. They click it. That's the moment the exposure begins — not because anyone did something reckless, but because the tools people trust most have quietly changed what they do with your data.
Tools that now have AI built in — whether you opted in or not:
Microsoft Excel / Word / Outlook (Copilot) Google Docs / Sheets / Gmail (Gemini) QuickBooks (Intuit AI) Adobe Acrobat (AI Assistant) Zoom (AI Companion)
None of these offer a BAA on free or personal-tier accounts. Most people never changed a single setting.

This pattern is showing up across every kind of South Dakota organization:

💊
Healthcare / Pharmacy
A pharmacy tech builds a controlled substance count log in Excel. They use the built-in Copilot AI to flag discrepancies and summarize monthly totals. Patient names and prescription details are now passing through Microsoft's AI layer — on a personal Microsoft account with no BAA.
PHI — HIPAA applies
⚖️
Law Firm / CPA Office
Staff uses ChatGPT Free to draft client letters, pasting in case summaries and financial details to get better output. No data processing agreement in place. QuickBooks AI features are used to categorize client invoices that include diagnosis codes.
Client PII / privileged data
🏫
School / Municipality
Administrator uses a free AI tool to summarize staff performance reviews or student records. The free tier has no retention controls or audit trail. Gemini in Google Workspace on a personal account is used to draft HR documents containing employee PII.
FERPA / employee records
What's actually at stake — 2026 HIPAA penalty schedule:
  • Fines from $145 to $73,011 per violation — even for violations you didn't know were happening (Tier 1)
  • Willful neglect that goes uncorrected: up to $2,190,294 per violation category per year
  • HIPAA breach notification — you must contact every affected individual
  • HHS Office for Civil Rights investigation — OCR enforcement timelines typically 12–24 months
  • Reputational damage — especially serious in a close-knit South Dakota community
  • Personal liability can extend to the individual who set up the tool
How the major AI tools compare
Google Gemini
Free / Workspace Personal
✗ No BAA
Trains on your dataYes (opt-out needed)
Data storageUnknown / varies
HIPAA useNot permitted
Safe for client PII?No
ChatGPT / Copilot
Free / Consumer Plans
⚠ Enterprise Only
Trains on your dataYes on free; opt-out on paid
BAA availableEnterprise only
HIPAA useEnterprise tier only
Safe for client PII?Enterprise only
Claude
Pro / Business / Teams
✓ BAA Available
Trains on your dataNo — never on paid plans
BAA availableYes — Business & Teams
HIPAA useSupported w/ BAA
Safe for client PII?Yes (paid plans)
Organizations doing this right
✓ What a responsible AI policy looks like in practice

Forward-thinking organizations are building approved tool lists — a short, vetted set of AI tools staff are permitted to use with client data, each with a signed BAA or DPA on file. Staff still use AI. Productivity goes up. But there's a clear line between "approved for client work" and "general use only — no identifying information." That policy doesn't require a big IT department. It requires someone willing to ask the question and document the answer. In most small organizations, that's a one-afternoon project.

What to do if you think you already had an exposure
If you're sitting here thinking "I may have already done this" — you're not alone, and the fact that you're asking the question puts you ahead of most. Don't panic, but don't ignore it either. Here's what to do.
1
Stop the bleeding immediately
Stop using that tool with that data right now. If the platform has a conversation history or data retention setting — check it. Some tools allow you to delete session data. Do it. Document what happened, what data was involved, and when.
2
Know the 4-factor test before you do anything else
Under HIPAA, not every accidental exposure automatically becomes a reportable breach. There is a formal 4-factor risk assessment that determines whether notification is required:
  1. What PHI was involved — type, sensitivity, volume
  2. Who accessed it — authorized party vs. unknown third party
  3. Was it actually viewed or acquired — or just briefly processed
  4. How much risk was mitigated — was data deleted, session cleared
3
Call a professional — not Google
This is not a situation to self-diagnose. Contact your compliance officer, HIPAA privacy officer, or a healthcare attorney before deciding whether you have a reportable incident. Do not self-report without guidance — but also do not simply hope nobody noticed. The documentation you create right now either helps or hurts you later.
Context matters — one slip is different from a pattern
A single accidental paste into a free AI tool carries very different risk than six months of staff doing it daily. HIPAA enforcement is largely complaint-driven and audit-triggered. Good-faith, isolated incidents that are promptly contained and documented are treated differently than systemic, ongoing neglect.
The honest bottom line: "I didn't know the AI was reading it" is not a permanent defense — but it's also not an automatic catastrophe. What turns an honest mistake into a serious liability is doing nothing about it. The organizations that face the hardest enforcement outcomes are the ones that knew or should have known and took no action.
The quick gut-check
Before you paste anything into a free AI tool, ask:
Something to think about
?
How many AI tools are being used in your organization right now — and does anyone know which ones have a signed BAA?
Most organizations have 3–8 AI tools in active use that were never formally reviewed. A 30-minute inventory conversation can close that gap before it becomes a problem.
The new frontier: third-party AI layers — and why they demand even more scrutiny
The BAA conversation above covers the tools you already use. But there is a second wave coming — and it is already arriving in South Dakota. Vendors are now actively selling AI layers that sit on top of your existing systems — your EHR, your accounting platform, your ag management software — and promise to summarize, analyze, and automate. The pitch is compelling. The questions nobody is asking are the ones that matter most.
🏥
AI that listens to your patient visits
Ambient AI scribes and EHR summarizers are being sold aggressively to clinics, counseling practices, and rural health organizations. They record, transcribe, and analyze provider-patient conversations.

Ask before you sign: Where are those recordings stored? What country are the servers in? Is the vendor subject to foreign government data requests? Does the model train on your session data?
PHI + privileged communications
🌾
AI that holds your land and soil data
Precision ag platforms collect soil samples, yield maps, application records, and generational land data. That data is genuinely valuable — to commodity traders, competitors, insurers, and foreign interests.

A third-party AI layer that aggregates your soil chemistry, drainage patterns, and yield history across multiple seasons is building a proprietary asset from your land — and most data agreements give them broad rights to it.
Proprietary land + competitive data
🌐
AI built overseas, sold locally
Cost pressure is driving small businesses toward cheaper AI solutions. Many of those solutions are built by vendors headquartered outside the US, with servers in jurisdictions that have very different rules about government data access.

The reputational risk alone — if your clients learned their data was stored on servers subject to a foreign government's access laws — is significant in a conservative, trust-based community like Mitchell.
Data sovereignty + reputational risk
⚖️ The cost trap small businesses keep falling into
The conversation in most small businesses goes: "Option A is $200/month and has all the right protections. Option B is $40/month and seems to do the same thing." Option B wins because nobody in the room has the framework to evaluate what's missing. Onsite vs. cloud. US-based servers vs. offshore. Dedicated instance vs. shared model training. BAA-eligible vs. not. These are not technical questions — they are business risk questions. And the gap between Option A and Option B is rarely $160/month when you factor in what's actually at stake.
QUESTIONS TO ASK ANY AI VENDOR BEFORE YOU SIGN
Where are your servers physically located — US, EU, or elsewhere?
Does my data leave a dedicated instance or go into a shared model?
Is my data used to train or fine-tune your AI model?
Will you sign a BAA or DPA — and which specific services does it cover?
What happens to my data if I cancel or the company is acquired?
Who are your subcontractors — and are they subject to the same terms?
Dakota Intelligence · Mitchell, SD
We help you navigate this — without the vendor pitch.
Dakota Intelligence uses Anthropic-based AI systems to analyze and assess your organization's AI readiness — then tells you plainly what you have, what you're missing, and where your vulnerabilities are. No upsell agenda. No preferred vendor kickbacks. Just a local, honest read on your situation.
AI Readiness Assessment — understand where you stand before you buy anything
Vendor Vetting — we evaluate AI tools against your specific compliance requirements and data profile
Architecture Guidance — onsite vs. cloud, US-based vs. offshore, dedicated vs. shared — framed as business decisions, not tech specs
Plain-Language Policy Building — one-page AI policies your staff will actually follow
Start here
Free 30-min consultation
No pitch. No pressure.
Just a plain-spoken local perspective.
Book a free call ↗
dakota-intelligence.com
605-273-8300

Sources & References